Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Evaluating A Selection of Tools for Extraction of Forensic Data: Disk ...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
1.19 TC-10-CorruptImage<br />
FTK Imager 2.9.0.1385 (Release Date: 8 th , Apr 2010)<br />
Test Case TC-10-CorruptImage (FTK Imager 2.9.0.1385)<br />
Test &<br />
Case<br />
Summary:<br />
Try verifying a corrupted image<br />
Notes: The image <strong>of</strong> FAT32 partition.<br />
Assertion: AFR-03 The tool operates in an execution environment<br />
AIC-06 If the image file integrity check is selected, the tool shall report<br />
to the user the image file has not been changed if the image file<br />
has not been changed.<br />
AIC-07 If the image file integrity check is selected, the tool shall report<br />
to the user the image file has been changed if the image file<br />
has been changed.<br />
AIC-08 If the image file integrity check is selected, the tool shall report<br />
to the user the image file has been changed and the involved<br />
location if the image file has been changed.<br />
ALOG-01 If the tool logs any in<strong>for</strong>mation regarding to the acquisition,<br />
the in<strong>for</strong>mation is accurately logged in the log file.<br />
ALOG-02 The tool display correct in<strong>for</strong>mation about the acquisition to<br />
the user.<br />
ALOG-03 The tool display correct in<strong>for</strong>mation regarding to the<br />
acquisition to the user and the in<strong>for</strong>mation displayed is<br />
Source<br />
Device:<br />
Drive<br />
Setup:<br />
Partition<br />
Setup:<br />
Log<br />
highlights:<br />
consistent with the log file if the log file function is supported<br />
Drive Model: ST380811 AS (80GB)<br />
Serial Number: 6PS2CA4Z<br />
Sector count: 156,296,385<br />
Write blocker: N/A<br />
Source image hashes<br />
MD5 checksum: 2c22fded78dc8ccc2c935944883a2e1b<br />
SHA1 checksum: 10eaa99a609cd8d215c9dc5a68f46e2e0d5c68c5<br />
Total sectors: 2104452 (1027MB)<br />
Address: Offset 35df5f70h Column 8 change byte from 43 to 42<br />
/dev/sda: current max LBA: 156,296,385<br />
/dev/sda: native max LBA: 156,296,385<br />
/dev/sda: physical max LBA: 156,296,385<br />
/dev/sda: HPA not set<br />
/dev/sda: DCO not set<br />
Device Start End #Sectors File System<br />
/dev/sda1 63 41945714 41945652 HPFS/NTFS<br />
/dev/sda2 4192965 156296384 152103420 Extended<br />
/dev/sda5<br />
/dev/sda6<br />
4193028<br />
6297543<br />
6297479<br />
10490444<br />
2104452<br />
4192902<br />
FAT32<br />
FAT16<br />
/dev/sda7 10490508 12594959 1052226 Ext2<br />
/dev/sda8 12595023 14699474 2104452 Ext3<br />
/dev/sda9 14699538 18892439 4192902 HPFS/NTFS<br />
/dev/sda10 18892503 19149479 256977 Swap<br />
unallocated 19149480 156296384 137146905 Empty<br />
Created By Access<strong>Data</strong>® FTK® Imager 2.9.0.1385 100406<br />
Notes: Acquire FAT32 partition only (sector first from 4193028 to<br />
6297479. total: 2104452).<br />
186